GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA DeepStream: crafted tensor dimensions in a YAML config trigger an integer overflow

CVSS 7.8CVE-2026-65102AI/ML frameworks & servingcurated

Impact

Crafted tensor dimensions in a DeepStream YAML configuration file cause an integer overflow, which NVIDIA says may lead to denial of service, information disclosure or data tampering. DeepStream pipelines run on GPU nodes and are typically driven by config files that select models and tensor shapes, so a tenant or operator who can supply that config can crash the pipeline or read memory it should not reach. NVIDIA rates it 7.8 local with low privileges; the record does not claim code execution, so treat this as a memory-safety bug reachable from configuration rather than a confirmed RCE.

Who can reach it

Local, authenticated: a user or pipeline able to provide the DeepStream YAML configuration the process parses. No user interaction beyond the service loading the config.

What to do

Update DeepStream to the fixed version listed in NVIDIA bulletin 2026/5886 and restart the DeepStream pipelines; this is a software update and process restart, not node maintenance. Until then, restrict write access to DeepStream configuration files to trusted operators and do not accept tenant-supplied pipeline configs.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.